Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
For more information, see KB51560
New features and enhancements
Customizable log file paths from CLI - You can now define a custom directory for product log files from the command-line interface.
Note
By default, the software stores logs in /var/McAfee/ens/log/
Bundle 6900 Anti-Malware Scan Engine - This release includes the 6900 Anti-Malware Scan Engine. The engine uses a Native Standard Template Library (STL) for improved performance and detection capabilities. This update modernizes core components to ensure better system compatibility and security posture.
Support for new distribution - This release introduces official compatibility for Ubuntu 26.4, Debian 13, and AlmaLinux 10.2.
Note
On Ubuntu 26.04, ensure that you install apt-utils before deploying Trellix Endpoint Security (ENS) for Linux .
apt-get install -y apt-utils
Extended Kernel Compatibility - This release adds compatibility for new kernels on Ubuntu 24.04 and Ubuntu 25.04. See Updated platform, environment, or operating system support for the complete list.
Resolved issues
Reference | Resolution |
|---|---|
ESFL-8484 | ENSL caused servers to stop responding during shutdown. Failures occurred when exploit prevention or access protection were active. Excessive event queuing during deregistration caused high system load. The software now disables the hook during deregistration. Disabling the hook ensures stability. |
ESFL-8220 | Resolved an issue where adaptive rules for ENSL did not appear in Trellix ePO - On-prem. The property translator task for the Firewall failed to process these rules. This failure occurred due to malformed JSON data. ENSL now uses correct data types for physical medium properties. These changes ensure rules translate correctly and appear in the console. |
Known issues
For a list of current known issues in Threat Prevention, see Trellix Knowledge Base article KB87518.
For a list of current known issues in Firewall, see Trellix Knowledge Base article KB91327.
Note
Before upgrading Trellix Endpoint Security (ENS) for Linux Firewall, see Trellix Knowledge Base article 000014500.
Updated platform, environment, or operating system support
This release includes additional kernel support. You can get the latest information about supported platforms, environments, and operating systems from the following links:
This release supports these additional kernel modules:
Ubuntu 24.04
6.17.0-14-generic
6.17.0-19-generic
6.17.0-20-generic
6.14.0-37-generic
6.17.0-22-generic
6.17.0-23-generic
6.17.0-29-generic
6.17.0-35-generic
6.17.0-40-generic
6.17.0-1013-aws
7.0.0-14-generic
Ubuntu 25.04
6.14.0-37-generic
Ubuntu 26.04
7.0.0-15-generic
Debian 13
6.12.38+deb13-amd64
AlmaLinux 10.2
6.12.0-211.30.1.el10_2.x86_64
Additional information
On Intel architecture, you must have installed Trellix Agent 5.6.4 (Build Number 110) (64-bit) or later to use this software.
On ARM architecture, you must have installed Trellix Agent 5.8.3 (Build Number 622) (64-bit) or later to use this software.